Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
profullstack
/
qryptchat-web
Public
Notifications
You must be signed in to change notification settings
Fork
27
Star
20
Code
Issues
0
Pull requests
0
Actions
Projects
Security and quality
17
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Actions: profullstack/qryptchat-web
Actions
All workflows
Workflows
codeql
codeql
Copilot cloud agent
Copilot cloud agent
security
security
test
test
threatcrush security scan
threatcrush security scan
Show more workflows...
Management
Caches
Deployments
threatcrush security scan
threatcrush security scan
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
threatcrush-scan.yml
will be ignored since log searching is not yet available
25 workflow runs
25 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
fix(ui): hide the feedback FAB on chat routes
threatcrush security scan
#25:
Pull request
#258
opened by
ralyodio
29s
worktree-hide-feedback-on-chat
worktree-hide-feedback-on-chat
29s
View #258
View workflow file
feat(settings): add encrypted key download to settings
threatcrush security scan
#24:
Pull request
#257
opened by
ralyodio
31s
worktree-key-export-ui
worktree-key-export-ui
31s
View #257
View workflow file
fix(crypto): stop republishing the public key on every login
threatcrush security scan
#23:
Pull request
#256
opened by
ralyodio
35s
fix/key-sync-overwrite
fix/key-sync-overwrite
35s
View #256
View workflow file
fix(db): restore message sending, broken by the SECURITY DEFINER revoke sweep
threatcrush security scan
#22:
Pull request
#255
opened by
ralyodio
29s
hotfix/message-send-permission
hotfix/message-send-permission
29s
View #255
View workflow file
fix(security): close conversation hijacking, profile mass assignment, avatar MIME trust
threatcrush security scan
#21:
Pull request
#254
opened by
ralyodio
34s
fix/security-advisories-wave3
fix/security-advisories-wave3
34s
View #254
View workflow file
fix(db): make the wave-2 policy migration idempotent against production
threatcrush security scan
#20:
Pull request
#253
opened by
ralyodio
33s
fix/migration-idempotent-policies
fix/migration-idempotent-policies
33s
View #253
View workflow file
fix(security): close the wave-2 advisories (RLS, XSS sink, token exposure, KDFs)
threatcrush security scan
#19:
Pull request
#252
opened by
ralyodio
31s
fix/security-advisories-wave2
fix/security-advisories-wave2
31s
View #252
View workflow file
chore(db): align the drop migration filename with the applied prod version
threatcrush security scan
#18:
Pull request
#251
opened by
ralyodio
35s
chore/align-drop-migration-version
chore/align-drop-migration-version
35s
View #251
View workflow file
fix(security): scope cleanup endpoints and harden backup PIN storage
threatcrush security scan
#17:
Pull request
#250
synchronize by
ralyodio
33s
fix/security-advisories-2026-08
fix/security-advisories-2026-08
33s
View #250
View workflow file
fix(security): scope cleanup endpoints and harden backup PIN storage
threatcrush security scan
#16:
Pull request
#250
opened by
ralyodio
34s
fix/security-advisories-2026-08
fix/security-advisories-2026-08
34s
View #250
View workflow file
fix(security): harden log_sms_notification and move SMS path to service role
threatcrush security scan
#15:
Pull request
#249
opened by
ralyodio
35s
security/sms-notification-hardening
security/sms-notification-hardening
35s
View #249
View workflow file
fix(security): bind the remaining IDOR-able RPCs to auth.uid()
threatcrush security scan
#14:
Pull request
#248
opened by
ralyodio
36s
security/bind-remaining-idors
security/bind-remaining-idors
36s
View #248
View workflow file
fix(security): revoke anon EXECUTE on the remaining 41 SECURITY DEFINER fns
threatcrush security scan
#13:
Pull request
#247
opened by
ralyodio
38s
security/sweep-remaining-secdef
security/sweep-remaining-secdef
38s
View #247
View workflow file
fix(db): drop the duplicated 20260814 migration files
threatcrush security scan
#12:
Pull request
#246
opened by
ralyodio
35s
fix/remove-duplicate-migrations
fix/remove-duplicate-migrations
35s
View #246
View workflow file
chore(db): align migration filenames with the applied prod versions
threatcrush security scan
#11:
Pull request
#245
opened by
ralyodio
30s
chore/align-migration-versions
chore/align-migration-versions
30s
View #245
View workflow file
fix(security): revoke anon RPC access, bind RPCs to auth.uid(), version RLS drift
threatcrush security scan
#10:
Pull request
#244
opened by
ralyodio
35s
security/remediation-steps-1-3
security/remediation-steps-1-3
35s
View #244
View workflow file
docs: archive the Noir0x63 security audit and its verification
threatcrush security scan
#9:
Pull request
#243
opened by
ralyodio
36s
worktree-docs-security-audit
worktree-docs-security-audit
36s
View #243
View workflow file
fix(settings): reject malformed retention JSON
threatcrush security scan
#8:
Pull request
#242
opened by
rissrice2105-agent
28s
rissrice2105-agent:fix/qryptchat-fifth-audit
rissrice2105-agent:fix/qryptchat-fifth-audit
28s
View #242
View workflow file
fix(groups): resolve internal user before listing
threatcrush security scan
#7:
Pull request
#240
opened by
rissrice2105-agent
29s
rissrice2105-agent:fix/group-list-internal-user-id
rissrice2105-agent:fix/group-list-internal-user-id
29s
View #240
View workflow file
fix(pwa): give maskable icons a real background and safe zone
threatcrush security scan
#6:
Pull request
#239
opened by
ralyodio
35s
worktree-maskable-icons
worktree-maskable-icons
35s
View #239
View workflow file
Fix profile validation for falsy non-string fields
threatcrush security scan
#5:
Pull request
#238
opened by
rissrice2105-agent
36s
rissrice2105-agent:fix/qryptchat-next-audit
rissrice2105-agent:fix/qryptchat-next-audit
36s
View #238
View workflow file
Icon pipeline → public/, delete static/, and run vitest in CI
threatcrush security scan
#4:
Pull request
#236
opened by
ralyodio
49s
worktree-icon-pipeline-and-ci
worktree-icon-pipeline-and-ci
49s
View #236
View workflow file
fix(pwa): restore installability lost in the Next.js migration
threatcrush security scan
#3:
Pull request
#235
opened by
ralyodio
32s
worktree-pwa-install-fix
worktree-pwa-install-fix
32s
View #235
View workflow file
fix(conversations): preserve two-member groups
threatcrush security scan
#2:
Pull request
#234
opened by
rissrice2105-agent
30s
rissrice2105-agent:fix/two-member-group-delete
rissrice2105-agent:fix/two-member-group-delete
30s
View #234
View workflow file
ci: add ThreatCrush security scan
threatcrush security scan
#1:
Pull request
#231
opened by
ralyodio
34s
chore/threatcrush-scan
chore/threatcrush-scan
34s
View #231
View workflow file
You can’t perform that action at this time.